๐Ÿ” CVE Alert

CVE-2026-64319

UNKNOWN 0.0

nvmet-auth: validate reply message payload bounds against transfer length

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
db1312dd95488b5e6ff362ff66fcf953a46b1821 < 80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0 db1312dd95488b5e6ff362ff66fcf953a46b1821 < 999f6205ede984a786f35f727b01f971b98e215d db1312dd95488b5e6ff362ff66fcf953a46b1821 < 6d7649c1231dac14d906985d2936967e23041c26 db1312dd95488b5e6ff362ff66fcf953a46b1821 < caa71b3a43ea5c13fe7141cb019ebcb03b8ac857 db1312dd95488b5e6ff362ff66fcf953a46b1821 < 3a413ece2504c70aa34a20be4dafec04e8c741f9
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0 git.kernel.org: https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d git.kernel.org: https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26 git.kernel.org: https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857 git.kernel.org: https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9